Junglewise Threat Intelligence

CVE-2025-68801: Linux Kernel mlxsw use-after-free in spectrum_router

CVE-2025-68801 · Severity: high · CVSS 7.8 · Published 2026-01-13

Technologies: Linux Kernel. Vendors: Linux.

Executive brief

A vulnerability in the Linux kernel's Mellanox Spectrum router driver could allow a local attacker to cause a system crash or potentially execute unauthorized code. The issue stems from how the system tracks network 'neighbors' (nearby devices on a network), leading to a memory error when the system tries to access information that has already been deleted. This could disrupt network operations or compromise the stability of data center switches using this hardware.

Technical details

A use-after-free vulnerability exists in the mlxsw_sp_neigh_entry_update function within the spectrum_router.c component of the Linux kernel. The root cause is a flawed reference counting scheme where the driver stores a pointer to a 'neighbour' structure without incrementing its reference count, leading to a dangling pointer when the neighbour is freed. An attacker with local access could trigger this condition during network configuration changes (e.g., RIF destruction or netdevice events), potentially leading to a kernel panic or local privilege escalation. The fix involves ensuring a reference is always taken when storing a neighbour pointer in a neighbour entry and properly releasing it during the entry's lifecycle.

Affected products

  • Linux Linux Kernel 6cf3c971dc84 to a2dfe6758fc63e542105bee8b17a3a7485684db0

Timeline

  • 2025-12-02: other: Patch authored
  • 2026-01-11: patched: Patch committed to stable tree
  • 2026-01-13: advisory: CVE published

References

Related threats